Vulnerability index

Browse CVEs

1,003 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Android CRITICAL 9.8
CVE-2021-25385

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers …

Mitigation only
Fix from $2,300 2021-06-11
Android CRITICAL 9.8
CVE-2021-25386

An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers …

Mitigation only
Fix from $2,300 2021-06-11
Chrome CRITICAL 9.6
CVE-2021-21201

Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 90.0.4430.72+
Fix from $2,300 2021-04-26
Chrome CRITICAL 9.6
CVE-2021-21223

Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially per…

Fix: 90.0.4430.85+
Fix from $2,300 2021-04-26
Chrome CRITICAL 9.6
CVE-2021-21226

Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially…

Fix: 90.0.4430.85+
Fix from $2,300 2021-04-26
Android CRITICAL 9.8
CVE-2021-0430

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio…

Patch available
Fix from $2,300 2021-04-13
Android CRITICAL 9.8
CVE-2021-25360

An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on …

Mitigation only
Fix from $2,300 2021-04-09
Android CRITICAL 9.8
CVE-2021-0396

In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an incorrect bo…

Mitigation only
Fix from $2,300 2021-03-10
Android CRITICAL 9.8
CVE-2021-0397EPSS 6%

In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with n…

Mitigation only
Fix from $2,300 2021-03-10
Android CRITICAL 9.8
CVE-2021-25346

A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

Mitigation only
Fix from $2,300 2021-03-04
Chrome CRITICAL 9.6
CVE-2021-21150

Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to …

Fix: 88.0.4324.182+
Fix from $2,300 2021-02-22
Chrome CRITICAL 9.6
CVE-2021-21151

Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HT…

Fix: 88.0.4324.182+
Fix from $2,300 2021-02-22
Chrome CRITICAL 9.6
CVE-2021-21154

Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to poten…

Fix: 88.0.4324.182+
Fix from $2,300 2021-02-22
Chrome CRITICAL 9.6
CVE-2021-21155

Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer proce…

Fix: 88.0.4324.182+
Fix from $2,300 2021-02-22
Chrome CRITICAL 9.6
CVE-2021-21142

Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a cra…

Fix: 88.0.4324.146+
Fix from $2,300 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21146

Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 88.0.4324.146+
Fix from $2,300 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21132EPSS 23%

Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $2,300 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21121EPSS 6%

Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a cra…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $2,300 2021-02-09
Chrome CRITICAL 9.6
CVE-2021-21124EPSS 8%

Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a s…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $2,300 2021-02-09
Android CRITICAL 9.8
CVE-2021-26687

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, the HostnameVerified default …

Mitigation only
Fix from $2,300 2021-02-04
Android CRITICAL 9.8
CVE-2021-26688

An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SM…

No fix yet
Fix from $2,300 2021-02-04
Android CRITICAL 9.8
CVE-2021-26689

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LV…

Mitigation only
Fix from $2,300 2021-02-04
Chrome CRITICAL 9.6
CVE-2020-16045

Use after Free in Payments in Google Chrome on Android prior to 87.0.4280.66 allowed a remote attacker who had compromised the renderer process to po…

Fix: 87.0.4280.66+
Fix from $2,300 2021-01-14
Android CRITICAL 9.8
CVE-2021-0316

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code exe…

Patch available
Fix from $2,300 2021-01-11
Android CRITICAL 9.8
CVE-2020-0471

In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper …

Patch available
Fix from $2,300 2021-01-11
Chrome CRITICAL 9.6
CVE-2021-21109

Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21110

Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a craft…

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21111

Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious exte…

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21115

User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potent…

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08
Chrome CRITICAL 9.6
CVE-2021-21106

Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially …

Fix: 87.0.4280.141+
Fix from $2,300 2021-01-08